
Data Protection
How we process and protect personal data.
Preamble
The following privacy policy is intended to inform you about the types of personal data (hereinafter also referred to as ‘data’) that we process, the purposes for which we do so, and the extent to which we process it. This privacy policy applies to all processing of personal data carried out by us, both in the context of providing our services and, in particular, on our websites, in mobile applications and within external online presences, such as our social media profiles (hereinafter collectively referred to as the “online offering”).
The terms used are not gender-specific.
Date: 8 July 2025
Data controller
USKA Union of Swiss Shortwave Amateurs
Head Office
Bahnhofstrasse 26
5000 Aarau
Email address: sekr@uska.ch
Legal notice: Legal notice
Overview of data processing
The following overview summarises the types of data processed and the purposes of such processing, and identifies the data subjects.
Types of data processed
- Master data.
- Payment data.
- Contact data.
- Content data.
- Contract data.
- Usage data.
- Meta, communication and procedural data.
- Image and/or video recordings.
- Audio recordings.
- Log data.
- Member data.
Categories of data subjects
- Service recipients and clients.
- Prospective clients.
- Communication partners.
- Users.
- Members.
- Business and contractual partners.
- Participants.
- Persons depicted.
Purposes of processing
- Provision of contractual services and fulfilment of contractual obligations.
- Communication.
- Security measures.
- Direct marketing.
- Office and organisational procedures.
- Organisational and administrative procedures.
- Firewall.
- Feedback.
- Surveys and questionnaires.
- Provision of our online services and user-friendliness.
- IT infrastructure.
- Public relations.
- Business processes and management procedures.
Relevant legal bases
Relevant legal bases under the Swiss Data Protection Act: If you are located in Switzerland, we process your data on the basis of the Federal Act on Data Protection (the ‘Swiss DPA’ for short). Unlike, for example, the GDPR, the Swiss Data Protection Act does not, in principle, require a legal basis for the processing of personal data to be specified, and stipulates that the processing of personal data must be carried out in good faith and must be lawful and proportionate (Art. 6(1) and (2) of the Swiss Data Protection Act). Furthermore, we only collect personal data for a specific purpose that is recognisable to the data subject and only process it in a manner compatible with that purpose (Art. 6(3) of the Swiss Data Protection Act).
Transfer of personal data
In the course of our processing of personal data, it may happen that such data is transferred to or disclosed to other bodies, companies, legally independent organisational units or individuals. Recipients of this data may include, for example, service providers commissioned to carry out IT tasks or providers of services and content integrated into a website. In such cases, we comply with the statutory requirements and, in particular, enter into appropriate contracts or agreements with the recipients of your data to ensure the protection of your data.
Data transfer within the organisation: We may transfer personal data to other departments or units within our organisation or grant them access to it. Where the transfer of data is for administrative purposes, it is based on our legitimate business and operational interests, or takes place where it is necessary to fulfil our contractual obligations, or where the data subjects have given their consent or where there is a legal authorisation.
Performance of duties in accordance with the Articles of Association or Rules of Procedure
We process the data of our members, supporters, prospective members, business partners or other individuals (collectively, ‘data subjects’) where we have a membership or other business relationship with them and are performing our duties, as well as where they are recipients of services and benefits. Furthermore, we process the data of data subjects on the basis of our legitimate interests, e.g. in the case of administrative tasks or public relations work.
The data processed in this context, as well as the nature, scope, purpose and necessity of such processing, are determined by the underlying membership or contractual relationship, from which the necessity of providing any data also arises (we will, moreover, indicate which data is required).
We delete data that is no longer required for the fulfilment of our statutory and business purposes. This is determined in accordance with the respective tasks and contractual relationships. We retain data for as long as it may be relevant for the conduct of business, as well as in respect of any warranty or liability obligations, based on our legitimate interest in regulating such matters. The necessity of retaining the data is reviewed on a regular basis; in all other respects, the statutory retention obligations apply.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Contract data (e.g. subject matter of the contract, term, customer category); membership data (e.g. personal data such as name, age, gender, contact details (email address, telephone number), membership number, information on membership fees, participation in events, etc.); Payment data (e.g. bank details, invoices, payment history). Content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation).
- Data subjects: Members.
- Purposes of processing: Communication. Organisational and administrative procedures.
- Retention and erasure: Erasure in accordance with the details set out in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Membership agreement (Articles of Association) (Article 6(1), first sentence, point (b) of the GDPR).
Further information on processing operations, procedures and services:
- Membership administration: Procedures required as part of membership administration include the recruitment and admission of new members, the development and implementation of strategies for member retention, and ensuring effective communication with members. These processes involve the careful collection and maintenance of membership data, the regular updating of membership information, and the administration of membership fees, including invoicing and accounting; Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR), membership agreement (Articles of Association) (Article 6(1), first sentence, point (b) of the GDPR).
Provision of the online service and web hosting
We process users’ data in order to provide them with our online services. For this purpose, we process the user’s IP address, which is necessary to transmit the content and functions of our online services to the user’s browser or device.
- Types of data processed: usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved); log data (e.g. log files relating to logins, data retrieval or access times); Content data (e.g. textual or visual messages and posts, as well as related information such as details of authorship or the time of creation); Master data (e.g. full name, residential address, contact details, customer number, etc.); Payment data (e.g. bank details, invoices, payment history); contact details (e.g. postal and email addresses or telephone numbers); contract data (e.g. subject matter of the contract, term, customer category).
- Data subjects: Users (e.g. website visitors, users of online services); service recipients and clients; prospective customers; business and contractual partners.
- Purposes of processing: Provision of our online services and user-friendliness; IT infrastructure (operation and provision of information systems and technical equipment (computers, servers, etc.)); Security measures; firewall; provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures. Business processes and business management procedures.
- Retention and erasure: Erasure in accordance with the details set out in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
Further information on processing operations, procedures and services:
- Provision of online services on leased storage space: To provide our online services, we use storage space, computing capacity and software which we lease or otherwise obtain from a relevant server provider (also known as a ‘web host’); Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Collection of access data and log files: Access to our online service is logged in the form of so-called ‘server log files’. Server log files may include the address and name of the web pages and files accessed, the date and time of access, the volume of data transferred, confirmation of successful access, browser type and version, the user’s operating system, the referrer URL (the previously visited page) and, as a rule, IP addresses and the requesting provider. The server log files may be used, on the one hand, for security purposes, e.g. to prevent server overload (particularly in the event of malicious attacks, known as DDoS attacks), and, on the other hand, to ensure server capacity utilisation and stability; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Deletion of data: Log file information is stored for a maximum of 30 days and is subsequently deleted or anonymised. Data which must be retained for evidential purposes is exempt from deletion until the relevant incident has been fully resolved.
- Email transmission and hosting: The web hosting services we use also include the sending, receiving and storage of emails. For these purposes, the addresses of the recipients and senders, as well as further information relating to the sending of emails (e.g. the providers involved) and the contents of the respective emails, are processed. The aforementioned data may also be processed for the purpose of detecting spam. Please note that emails are generally not sent in encrypted form over the internet. Although emails are usually encrypted whilst in transit, they are not encrypted on the servers from which they are sent and received (unless a so-called end-to-end encryption method is used). We are therefore unable to accept any responsibility for the transmission of emails between the sender and our server; legal basis: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
- Wordfence: Firewall, security and intrusion detection functions to detect and prevent unauthorised access attempts, as well as technical vulnerabilities that could enable such access. For these purposes, cookies and similar storage methods required for this purpose may be used, and security logs may be generated during the monitoring process and, in particular, in the event of unauthorised access. In this context, users’ IP addresses, a user identification number and their activities – including the time of access – are processed and stored, and are compared with the data provided by the provider of the firewall and security functions and transmitted to that provider; Service provider: Defiant, Inc., 800 5th Ave Ste 4100, Seattle, WA 98104, USA; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.wordfence.com; Privacy policy: https://www.wordfence.com/privacy-policy/; Basis for transfers to third countries: Standard contractual clauses (https://www.wordfence.com/standard-contractual-clauses/), Standard contractual clauses (https://www.wordfence.com/standard-contractual-clauses/). Further information: https://www.wordfence.com/help/general-data-protection-regulation/.
- Events Manager for WordPress: Creation and management of events, bookings and registrations; integration of payment gateways for ticket sales; creation of event pages with maps and calendars; management of venues and organisers; email notifications and reminders; export and import of event data; service provider: processing carried out on servers and/or computers under the provider’s own data protection responsibility; legal bases: performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR), legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Website: https://wp-events-plugin.com/.
- Hostpoint: Services relating to the provision of IT infrastructure and associated services (e.g. storage space and/or computing capacity); Service provider: Hostpoint AG, Neue Jonastrasse 60, 8640 Rapperswil-Jona, Switzerland; Legal bases: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://support.hostpoint.ch/de/. Privacy policy: https://www.hostpoint.ch/hostpoint/kontakt-agb.html#datenschutz.
- WP Super Cache: Caching and loading optimisation – functions designed to store certain website content so that it can be loaded more quickly upon repeated access. This reduces loading times and improves the user experience; Service provider: Processing carried out on servers and/or computers under the provider’s own responsibility under data protection law; Legal basis: Legitimate interests (Art. 6(1), first sentence, (f) of the GDPR). Website: https://wordpress.org/plugins/wp-super-cache/.
Registration, login and user account
Users may create a user account. During registration, users are informed of the required mandatory details, which are processed for the purpose of providing the user account on the basis of the fulfilment of contractual obligations. The data processed includes, in particular, login details (username, password and an email address).
When using our registration and login functions, as well as when using the user account, we store the IP address and the time of the respective user action. This data is stored on the basis of our legitimate interests, as well as those of the users, in protection against misuse and other unauthorised use. As a general rule, this data is not disclosed to third parties, unless this is necessary to pursue our claims or there is a legal obligation to do so.
Users may be informed by email about matters relevant to their user account, such as technical changes.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Log data (e.g. log files relating to logins, data retrieval or access times).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; security measures; organisational and administrative procedures. Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the details in the section ‘General information on data storage and erasure’. Erasure following termination.
- Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR). Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Registration using real names: Due to the nature of our community, we ask users to use our service only under their real names. This means that the use of pseudonyms is not permitted; Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
- User profiles are not public: User profiles are not publicly visible or accessible.
- Deletion of data following termination: Once users have terminated their user account, their data relating to that account will be deleted, subject to any statutory authorisation, obligation or the user’s consent; Legal bases: performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
- No obligation to retain data: It is the users’ responsibility to back up their data prior to the end of the contract in the event of termination. We are entitled to irrevocably delete all of the user’s data stored during the term of the contract; Legal basis: performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
Contact and enquiry management
When contacting us (e.g. by post, contact form, email, telephone or via social media), as well as in the context of existing user and business relationships, the details of the enquirers are processed to the extent necessary to respond to contact enquiries and any requested actions.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing: communication; organisational and administrative procedures; feedback (e.g. collecting feedback via an online form). Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Performance of a contract and pre-contractual enquiries (Article 6(1), first sentence, point (b) of the GDPR).
Further information on processing operations, procedures and services:
- Contact form: When you contact us via our contact form, by email or through other communication channels, we process the personal data provided to us in order to respond to and deal with your enquiry. This generally includes details such as your name, contact details and, where applicable, any further information provided to us that is necessary for the appropriate handling of your enquiry. We use this data exclusively for the stated purpose of establishing contact and communication; Legal bases: Performance of a contract and pre-contractual enquiries (Art. 6(1), first sentence, point (b) of the GDPR), legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR).
- Formcraft: web form; service provider: Subtle Web Inc, 225 Railway St E, T4C 2C3, Cochrane, AB. Website: https://formcraft-wp.com.
Video conferences, online meetings, webinars and screen sharing
We use platforms and applications from other providers (hereinafter referred to as “conference platforms”) for the purpose of conducting video and audio conferences, webinars and other types of video and audio meetings (hereinafter collectively referred to as “conferences”). When selecting conference platforms and their services, we comply with the relevant legal requirements.
Data processed by conference platforms: When participants take part in a conference, the conference platforms process the personal data of the participants listed below. The scope of the processing depends, on the one hand, on which data is required for a specific conference (e.g. provision of login details or real names) and what optional information is provided by participants. In addition to processing for the purpose of conducting the conference, participants’ data may also be processed by the conference platforms for security purposes or to optimise the service. The data processed includes personal details (first name, surname), contact information (email address, telephone number), login details (access codes or passwords), profile pictures, details of professional status/role, the IP address of the internet connection, details of participants’ devices, their operating system, browser and its technical and language settings, information on the content of communications, i.e. inputs in chats as well as audio and video data, and the use of other available functions (e.g. surveys). The content of communications is encrypted to the extent technically provided by the conference providers. If participants are registered as users on the conference platforms, further data may be processed in accordance with the agreement with the respective conference provider.
Logging and recordings: Should text entries, participation results (e.g. from surveys) and video or audio recordings be logged, participants will be informed of this transparently in advance and, where necessary, asked for their consent.
Participants’ data protection measures: Please refer to the conference platforms’ privacy policies for details regarding the processing of your data and select the security and privacy settings that best suit your needs within the conference platforms’ settings. Please also ensure that your data and privacy are protected in the background of your recording for the duration of a video conference (e.g. by informing housemates, locking doors and, where technically possible, using the function to blur the background). Links to the conference rooms and access details must not be passed on to unauthorised third parties.
Notes on legal bases: Where, in addition to the conferencing platforms, we also process users’ data and ask users for their consent to the use of the conferencing platforms or certain functions (e.g. consent to the recording of conferences), the legal basis for the processing is this consent. Furthermore, our processing may be necessary to fulfil our contractual obligations (e.g. in participant lists, when summarising the results of discussions, etc.). In all other respects, users’ data is processed on the basis of our legitimate interests in efficient and secure communication with our communication partners.
- Types of data processed: Personal details (e.g. full name, home address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions); Image and/or video recordings (e.g. photographs or video recordings of a person); audio recordings; log data (e.g. log files relating to logins, data retrieval or access times). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, individuals involved).
- Data subjects: Communication partners; users (e.g. website visitors, users of online services). Persons depicted.
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations; communication; office and organisational procedures. Provision of our online services and user-friendliness.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- BigBlueButton: BigBlueButton is an open-source web conferencing system. In addition to various web conferencing services, it offers integrations with many of the leading learning and content management systems; Service provider: Operated on servers and/or computers under the provider’s own data protection responsibility; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR). Website: https://bigbluebutton.org/.
Newsletters and electronic notifications
We send out newsletters, emails and other electronic notifications (hereinafter “newsletters”) exclusively with the recipients’ consent or on a legal basis. Where the content of the newsletter is specified during the subscription process, this content is decisive for the users’ consent. To subscribe to our newsletter, providing your email address is normally sufficient. However, in order to offer you a personalised service, we may ask you to provide your name so that we can address you personally in the newsletter, or to provide further information if this is necessary for the purpose of the newsletter.
Deletion and restriction of processing: We may store unsubscribed email addresses for up to three years on the basis of our legitimate interests before deleting them, in order to be able to provide evidence of consent previously given. The processing of this data is limited to the purpose of potentially defending against claims. An individual request for erasure may be made at any time, provided that the prior existence of consent is confirmed at the same time. In the event of obligations to permanently comply with objections, we reserve the right to store the email address solely for this purpose in a blocklist.
The logging of the registration process is carried out on the basis of our legitimate interests for the purpose of proving that it was carried out correctly. Where we commission a service provider to send emails, this is done on the basis of our legitimate interests in an efficient and secure delivery system.
Content:
Information about us, our services, promotions and offers.
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers). Meta, communication and process data (e.g. IP addresses, timestamps, identification numbers, persons involved).
- Data subjects: Communication partners.
- Purposes of processing: Direct marketing (e.g. by email or post).
- Legal basis: Consent (Article 6(1)(a) of the GDPR).
- Right to object (opt-out): You may unsubscribe from our newsletter at any time, i.e. withdraw your consent or object to receiving further issues. You will find a link to unsubscribe from the newsletter either at the end of each newsletter or you can use one of the contact options listed above, preferably by email.
Further information on processing operations, procedures and services:
- Mailster – Email Newsletter Plugin for WordPress: Newsletter; service provider: EverPress, Bauernstraße 1, Wels 4600, Austria. Website: https://mailster.co.
Surveys and questionnaires
We conduct surveys and questionnaires to collect information for the specific purpose stated in each survey or questionnaire. The surveys and questionnaires we conduct (hereinafter “surveys”) are analysed anonymously. Personal data is processed only to the extent necessary for the provision and technical implementation of the surveys (e.g. processing of the IP address to display the survey in the user’s browser or to enable the survey to be resumed using a cookie).
- Types of data processed: Master data (e.g. full name, residential address, contact details, customer number, etc.); contact details (e.g. postal and email addresses or telephone numbers); Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Participants. Users (e.g. website visitors, users of online services).
- Purposes of processing: Feedback (e.g. collecting feedback via an online form). Surveys and questionnaires (e.g. surveys with text fields, multiple-choice questions).
- Retention and deletion: Deletion in accordance with the information provided in the section ‘General information on data storage and deletion’.
- Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- UmfrageOnline: Conducting online surveys; service provider: enuvo GmbH, Huobstrasse 10, 8808 Pfäffikon SZ, Switzerland; Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Website: https://www.umfrageonline.com/. Privacy policy: https://www.umfrageonline.com/datenschutz.
Social media presence
We maintain an online presence on social media platforms and, in this context, process user data in order to communicate with users active on these platforms or to provide information about us.
Please note that user data may be processed outside the European Union in this context. This may entail risks for users, as it could, for example, make it more difficult to enforce their rights.
Furthermore, users’ data within social media platforms is generally processed for market research and advertising purposes. For example, usage profiles may be created based on users’ behaviour and the resulting interests. These profiles may in turn be used, for example, to display adverts within and outside the networks that are presumed to correspond to users’ interests. Consequently, cookies are usually stored on users’ computers, in which their usage behaviour and interests are recorded. In addition, data may also be stored in the usage profiles regardless of the devices used by users (particularly if they are members of the respective platforms and are logged in there).
For a detailed description of the respective forms of processing and the options for objecting (opt-out), please refer to the privacy policies and information provided by the operators of the respective networks.
We would also like to point out that, in the case of requests for information and the exercise of data subjects’ rights, these can most effectively be exercised with the providers themselves. Only the latter have access to the users’ data and can take appropriate action and provide information directly. Should you nevertheless require assistance, please do not hesitate to contact us.
- Types of data processed: Contact details (e.g. postal and email addresses or telephone numbers); content data (e.g. text-based or image-based messages and posts, as well as related information such as details of authorship or the time of creation). Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions).
- Data subjects: Users (e.g. website visitors, users of online services).
- Purposes of processing: Communication; feedback (e.g. collecting feedback via an online form). Public relations.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal basis: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Facebook pages: Profiles within the Facebook social network – We are jointly responsible with Meta Platforms Ireland Limited for the collection (but not the further processing) of data relating to visitors to our Facebook page (known as a “fan page”). This data includes information on the types of content that users view or interact with, or the actions they take (see ‘Things you and others do and share’ in the Facebook Data Policy: https://www.facebook.com/privacy/policy/), as well as information about the devices used by users (e.g. IP addresses, operating system, browser type, language settings, cookie data; see ‘Device information’ in the Facebook Data Policy: https://www.facebook.com/privacy/policy/). As explained in the Facebook Data Policy under ‘How do we use this information?’, , Facebook also collects and uses information to provide analytics services, known as ‘Page Insights’, to page administrators, so that they can gain insights into how people interact with their pages and the content associated with them. We have entered into a specific agreement with Facebook (“Information on Page Insights”, https://www.facebook.com/legal/terms/page_controller_addendum), which specifically sets out the security measures Facebook must observe and in which Facebook has agreed to comply with data subjects’ rights (i.e. users can, for example, submit requests for information or erasure directly to Facebook). Users’ rights (in particular the rights to access, erasure, objection and to lodge a complaint with the competent supervisory authority) are not restricted by the agreements with Facebook. Further information can be found in the “Page Insights Information” (https://www.facebook.com/legal/terms/information_about_page_insights_data). Joint controllership is limited to the collection by and transfer of data to Meta Platforms Ireland Limited, a company based in the EU. Further processing of the data is the sole responsibility of Meta Platforms Ireland Limited, in particular with regard to the transfer of data to the parent company, Meta Platforms, Inc., in the USA; Service provider: Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Ireland; Legal basis: Legitimate interests (Art. 6(1), first sentence, point (f) of the GDPR); Website: https://www.facebook.com; Privacy policy: https://www.facebook.com/privacy/policy/. Basis for transfers to third countries: Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum), Data Privacy Framework (DPF), Standard Contractual Clauses (https://www.facebook.com/legal/EU_data_transfer_addendum).
- YouTube: social network and video platform; service provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; legal bases: legitimate interests (Article 6(1), first sentence, point (f) of the GDPR); Privacy policy: https://policies.google.com/privacy; Basis for transfers to third countries: Data Privacy Framework (DPF), Data Privacy Framework (DPF). Right to object (opt-out): https://myadcenter.google.com/personalizationoff.
Management, organisation and support tools
We use services, platforms and software from other providers (hereinafter referred to as ‘third-party providers’) for the purposes of organising, administering, planning and delivering our services. When selecting third-party providers and their services, we comply with the relevant legal requirements.
In this context, personal data may be processed and stored on the third-party providers’ servers. This may affect various types of data which we process in accordance with this privacy policy. Such data may include, in particular, users’ master data and contact details, as well as data relating to transactions, contracts, other processes and their contents.
Where users are referred to third-party providers or their software or platforms in the course of communication, business or other relationships with us, the third-party providers may process usage data and metadata for security purposes, to optimise their services or for marketing purposes. We therefore ask that you observe the privacy policies of the respective third-party providers.
- Types of data processed: Content data (e.g. text or image-based messages and posts, as well as related information such as details of authorship or the time of creation); Usage data (e.g. page views and time spent on the site, click paths, usage intensity and frequency, types of devices and operating systems used, interactions with content and functions). Meta, communication and procedural data (e.g. IP addresses, time stamps, identification numbers, persons involved).
- Data subjects: Communication partners. Users (e.g. website visitors, users of online services).
- Purposes of processing: Provision of contractual services and fulfilment of contractual obligations. Office and organisational procedures.
- Retention and erasure: Erasure in accordance with the information provided in the section ‘General information on data storage and erasure’.
- Legal bases: Legitimate interests (Article 6(1), first sentence, point (f) of the GDPR).
Further information on processing operations, procedures and services:
- Fairgate: Association management software; service provider: Fairgate AG, Spinnereiweg 2, 8307 Effretikon. Website: https://fairgate.ch.
Amendments and updates
We ask you to check the content of our privacy policy regularly. We will amend the privacy policy as soon as changes to the data processing activities we carry out make this necessary. We will inform you as soon as the changes require an action on your part (e.g. consent) or any other individual notification.
Where we provide addresses and contact details for companies and organisations in this privacy policy, please note that these details may change over time; we therefore ask you to check the information before making contact.
